Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-2597

Опубликовано: 12 июн. 2010
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The TIFFVStripSize function in tif_strip.c in LibTIFF 3.9.0 and 3.9.2 makes incorrect calls to the TIFFGetField function, which allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image, related to "downsampled OJPEG input" and possibly related to a compiler optimization that triggers a divide-by-zero error.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 3libtiffNot affected
Red Hat Enterprise Linux 6libtiffNot affected
Red Hat Enterprise Linux 4libtiffFixedRHSA-2010:051908.07.2010
Red Hat Enterprise Linux 5libtiffFixedRHSA-2010:051908.07.2010

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=610776libtiff: use of uninitialized values crash

EPSS

Процентиль: 87%
0.03306
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 15 лет назад

The TIFFVStripSize function in tif_strip.c in LibTIFF 3.9.0 and 3.9.2 makes incorrect calls to the TIFFGetField function, which allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image, related to "downsampled OJPEG input" and possibly related to a compiler optimization that triggers a divide-by-zero error.

nvd
почти 15 лет назад

The TIFFVStripSize function in tif_strip.c in LibTIFF 3.9.0 and 3.9.2 makes incorrect calls to the TIFFGetField function, which allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image, related to "downsampled OJPEG input" and possibly related to a compiler optimization that triggers a divide-by-zero error.

debian
почти 15 лет назад

The TIFFVStripSize function in tif_strip.c in LibTIFF 3.9.0 and 3.9.2 ...

github
около 3 лет назад

The TIFFVStripSize function in tif_strip.c in LibTIFF 3.9.0 and 3.9.2 makes incorrect calls to the TIFFGetField function, which allows remote attackers to cause a denial of service (application crash) via a crafted TIFF image, related to "downsampled OJPEG input" and possibly related to a compiler optimization that triggers a divide-by-zero error.

oracle-oval
почти 15 лет назад

ELSA-2010-0519: libtiff security update (IMPORTANT)

EPSS

Процентиль: 87%
0.03306
Низкий

4.3 Medium

CVSS2